#room-bugs

1 messages Β· Page 30 of 1

glossy crane
#

Same thing happened when studying XSS practical example (blind xss) task 8

#

I set up 2 tickets, one for the nc and one for the server in different ports

#

You can see the payload at the bottom just in case i am making any mistakes but i believe is ok.

#

Then the system should get me the cookie back but it doesn’t arrives

#

I have try with and WITHOUT my VPN and it doesn’t work

#

I do have a cookie for the ticket

#

No no i dont recieve anything on the listeners

#

What do you mean by my own cookie?

#

No that doesn’t happen

#

Done

#

But still getting nothing

#

@vital vine

#

on it, let me see

#

that actually did solve the problem

#

still wondering if i did something similar with the DogCat room

#

yes SADLY I did get my own cookie

#

Anyway Lassi thanks for your help and your patience, you are always available and always willing to help.... it is much appreciated by the community blobheart

#

@vital vine

#

New cookie not coming through so i will restart the machine and try again

obsidian kiln
#

I've got this sorted πŸ™‚
Should now deploy with internet access

glossy crane
#

great @obsidian kiln

#

Unfortunately restarting the machine doesn't do anything, still not getting the cookie (restarted it twice)

#

will do

left tendon
#

yuuusss - thanks @obsidian kiln

lost robin
#

Hello all
I have a problem in the room https://tryhackme.com/room/kenobi I'm at the end of logging into ssh, when I want to log in using the gained file id_rsa from target ,
I keep getting a message " sign_and_send_pubkey: no mutual signature supported"

used command: " ssh -i id_rsa kenobi@ip

What could be wrong? Thanks !

#

I checked the answer pages, I did everything correctly, like everyone else.

left tendon
#

@lost robin i just checked this and it works fine. want to debug via dm?

lost robin
strong shard
crystal gorge
#

But hey, correct me if I'm wrong!

eternal summit
#

If you refresh the page, it'll replace it with the correct answer

crystal gorge
#

Oh okay I didn't know that, thanks!

jaunty knot
#

I finished the burp room a couple of days ago I even got an email confirmation that I got a badge as a reward for the finished room. And now all of a sudden that room is completely erased for me (as if I never did it).

eternal summit
jaunty knot
livid escarpBOT
#

Gave +1 Rep to @eternal summit

strong shard
rugged canyon
#

also means that it is probably outdated and might be getting updated or the owner don't want you to access it anymore for multiple different reasons

strong shard
#

thanks for your feedback.

eternal summit
strong shard
eternal summit
#

@obsidian kiln

eternal summit
strong shard
#

oh , am so stupid

#

thanks for clarifying things

obsidian kiln
#

🀣 got another one 😁

strong shard
#

thanks @eternal summit

livid escarpBOT
#

Gave +1 Rep to @eternal summit

strong shard
#

thanks @obsidian kiln for the great content you're making for beginners like me

obsidian kiln
#

Pleasure :)
Glad you're enjoying it!

quaint sparrow
hazy tiger
#

@icy elbow

#

@queen sphinx

rugged canyon
#

@icy elbow ⬆️ hope you still around to do cleanup

#

damn jabba was quicker on the trigger

livid escarpBOT
#
Ban <User:Mention/ID> [Reason:Text]

[-d d:Duration - Duration]
[-ddays ddays:Whole number - Delete Days]

Invalid arguments provided: "nitro" is not a whole number
icy elbow
#

-ban 781813619440615466 -ddays 1 nitro scam.

livid escarpBOT
#

πŸ”¨ Banned prolomic#6047 indefinitely

icy elbow
#

baai

bitter badger
#

In the Jr Pentester path and module BurpSuite The Basics, the Bastion website is broken. If it loads it will crash when navigating through the homepage.

white wren
#

I notice something still not fix until this day. When I put an answer with faster typing and enter. The answer miss last letter like this

eternal summit
hazy tiger
dusky junco
hazy tiger
#

Whoops, I missed the close brace

hazy tiger
#

Unless I'm crazy?

dusky junco
#

damn what

#

Unless there's whitespace in the answer that you're providing?

hazy tiger
#

No, even the user I'm communicating w/ has tried it

#

No go

#

Honestly can't figure out what's wrong

sonic willow
#

your β€˜ looks weird

dusky junco
#

I've literally just answreed it

hazy tiger
quaint sparrow
#

Would answer tolerance only kick in for alphanumerical characters?

hazy tiger
#

God knows

dusky junco
#

Yeah the ' looks curly so idk how that works

#

or a comma , but upper instead

#

is that what the static site gives as the flag?

hazy tiger
#

According to them, yes

#

And the writeup I read, also yes

#

But nobody else has had this problem so idk

dusky junco
#

If I can find the source code for the static site I'll take a look and make an edit

#

I can see the site but the title does not match to a source code directory KEKW

#

I'll take a look later I need to go do stuff

#

like laundry

#

how exciting

hazy tiger
#

No rush :)

eternal summit
gilded sentinel
#

Hello boys, I got a 502 code on the junior pentester path burp suite : repeater. I reboot 2 times the VM but I got always 502 code

#

Did I do something wrong ?

#

It's OK ! It's time to load (around 3/4 minutes πŸ˜‰ )

obsidian kiln
#

One sec, I'll have a play with the specs and see if I can speed it up a bit

gilded sentinel
obsidian kiln
#

Uhhh, thanks

#

There we go. Just convinced it to boot in a minute @gilded sentinel πŸ™‚

livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

tawny axle
#

hi guys, im doing the room ice and i got a problem when i try to execute the exploit in msfconsole.
when im running the exploit instead of giving me a meterpreter, im getting this error: Exploit completed, but no session was created.

#

can someone help me with that?

eternal summit
strong shard
#

Hello , i've finished the Burp suite module but am still getting notification on the right hand side (Next Achievement (2/4) Burp'ed) as you can see in the picture :
https://imgur.com/po0u8IE.png

white osprey
#

Hey!

the room https://tryhackme.com/room/learnssti

Task 2 question 1 straight up gives you the answer within the answer box. Not sure if intentional. I know it's a learning box.

median coral
bitter raptor
sonic willow
dusky junco
#

-ban 696286897164517396 -ddays 1 scam/phishing link. Please secure your account and appeal the ban at bans@tryhackme.com

livid escarpBOT
#

πŸ”¨ Banned Mon#4335 indefinitely

dusky junco
#

-ban 861161218962489354 -ddays 1 nitro spam

livid escarpBOT
#

πŸ”¨ Banned KDReddy#4860 indefinitely

wheat fractal
#

@white osprey hehe thats is cause the The hints show up which brackets u have to use... it is intentional its like flag Hints with the {********}

royal grail
#

will someone make this room public again

#

i cant move on without completeing Cc:Pentesting and the owner made it private

quaint sparrow
#

replace /home/ with /jr/

#

or is it room....

#

Possibly could be could room

median coral
#

Telling people to join private rooms smh

quaint sparrow
#

Good job you're not a mod then, eh?

median coral
#

I do it all the time

dusky junco
#

especially with ones that have gone from public -> private. They're now private for very good reasons

#

old, outdated content, content not working, etc.

quaint sparrow
#

Yeah, but someone was asking for that room yesterday as they needed to do it for school, I think, and James told them to use that trick, I just assumed it was okay.

My mistake if it isn't.

eternal summit
dusky junco
#

education customers are different

#

they have the ability to clone rooms and have dedicated support

eternal summit
quaint sparrow
#

So, going forward from me, would you like me to stop telling people to replace /room/ ?

dusky junco
quaint sparrow
dusky junco
#

It's okay Scrubz (: thanks for your efforts

#

If it's a room you've done before, no reason why you can't help out if you want to. Just saying that thm don't provide help, unless it's business/education and they have their own channels/means to get that help πŸ‘

royal grail
raw bison
# royal grail

@dusky junco Maybe even to change the whole question to something that doesn't have to get updated periodically, since as far as I remember that question had to get updated previously already, just as a suggestion πŸ™‚

dense garnet
fading drum
#

Hello, Mitre room is really outdated and you can no longer answer questions with information on Mitre ATT&CK webside (wich is required)

#

Good example is task 3

#

Question 5 and 6

#

now, if you cheat like I do and get answer for question 5, next question is : Based on the information for this group, what are their associated groups?

#

That information have long since been updated and can no longer give you "Correct" answer

rotund burrow
#

Heh i'm exactly at that task πŸ˜„ i guess there are some old writeups for it where can i get the answers?

fading drum
#

The answers, but my whole class got this room as homework and its a bit sad that we have to resort to cheating

rotund burrow
livid escarpBOT
#

Gave +1 Rep to @fading drum

fading drum
#

please, THM staff, fix the room when you have time

#

@lucid oasis angryping blobheart

eternal summit
#

That'd really be a thing for @glad badger

drowsy gale
drowsy gale
#

https://tryhackme.com/room/owaspjuiceshop Task4 Q1 - best1050.txt from Seclists is not available either via 'apt-get install seclists' or supposed location of /usr/share/seclists/... it's actually located in /usr/share/wordlists/dirb/others/best1050.txt

glad badger
drowsy gale
#

Task4 Q1 might as well be removed since the brute force with burp community seems like it will take hours, not really a foundation task.

#

another broken flag for juiceshop...skipping entire room

rugged canyon
#

yeah that room is finicky

#

and might need an update of the juice shop instance it is running for better results

#

you can brute force it using hydra instead which should speed it up significantly

drowsy gale
#

the 'complete beginner' path seems jumbled up entirely, fundamental rooms requiring that you do separate rooms for gobuster (not in beginners path) and what the shell before starting it, network exploitation basics requiring rooms further down the list to be done first.

eternal summit
fading drum
drowsy gale
eternal summit
#

It's not my front page, I'm not THM.

drowsy gale
#

obviously i'm not saying it's you

eternal summit
#

I don't work for THM either, I'm just relaying information that went out by email likely before you joined.

drowsy gale
#

and i'm just a paying customer relaying my views

obsidian kiln
drowsy gale
#

noted, strayed off a bit from original issues

quaint sparrow
#

@eternal summit

fading drum
#

what kind of virus is this?

quaint sparrow
eternal summit
#

-ban @hearty onyx -ddays 1 Nitro phishing. Please secure your account and then appeal this ban by emailing bans@tryhackme.com

livid escarpBOT
#

πŸ”¨ Banned KOBE#4475 indefinitely

eternal summit
fading drum
#

trying to steal steam account πŸ˜„

eternal summit
obsidian kiln
# eternal summit Discord account usually

Tbf, they usually go for steam as well, and steam phishes are still really common.
Might as well grab both tokens at once if you're gonna infect them with a token stealer, I guess?

eternal summit
#

Depends whether it's actually distributing malware or just phishing

obsidian kiln
#

True

dusky junco
#

-ban 434572036807983107 -ddays 1 nitro scam

livid escarpBOT
#

πŸ”¨ Banned codecesar#0033 indefinitely

eternal summit
#

@obsidian kiln can you ban that URL entirely plz?

obsidian kiln
#

I can indeed

eternal summit
#

-ban @kind tartan -ddays 1 Nitro phishing. Please secure your account and then appeal this ban by emailing bans@tryhackme.com

livid escarpBOT
#

πŸ”¨ Banned Preston#4761 indefinitely

magic nebula
#

Hey, the deployed machine in Phishing room isnt working.

unreal hemlock
#

cyborg machine have a bug ?

fading drum
#

Web Fundamentals path. I have completed "how websides work" room but it appears to be not completed

#
  • as I click it, it says 100% and all the tasks are x8
celest lotus
#

Anyone tried to complete : Kubernetes for Everyone Room ?

#

Cause there is a problem with the server

#

I get : Error from server: error dialing backend: dial tcp 10.0.2.15:10250: i/o timeout
After running this : k0s kubectl exec -it kube-api -n kube-system -- /bin/bash

eternal summit
celest lotus
#

yes

eternal summit
#

This looks like user error rather than a bug with the machine, please ask for help in #972196220485373982

dense garnet
celest lotus
#

tried also with the ubuntu machine of tryhackme, and kali linux of tryhackme and got the exact same problem

median coral
dense garnet
celest lotus
#

that was very easy

#

but my problem is how can i fix the bug i'm getting

dense garnet
median coral
celest lotus
#

and give it a try

#

thanks

dense garnet
celest lotus
livid escarpBOT
#

Gave +1 Rep to @dense garnet

wheat fractal
#

Room howwebsiteswork contains a bug -> duplicated tasks 8x

floral gorge
#

Hi don't the qusrions in room howwesiteworks

#

Only the first

#

all the tasks are completed but the room does not appeared completed !

#

in my path

#

complete beginner

fervent marsh
#

hi , howwebsiteswork room has an issue

#

each task appears 5 times so, i cannot finish the room

dusky junco
#

hi, this has already been reported and it's being looked into. Ta (: @floral gorge @fervent marsh

#

cc @wheat fractal

fervent marsh
#

okay, thanks

crimson tendon
royal grail
royal grail
#

can someone fix the image pls

glad badger
livid escarpBOT
#

Gave +1 Rep to @royal grail

quaint bone
#

Task 6 in metasploit exploitation (https://tryhackme.com/room/metasploitexploitation#) :

"Transfer it to the target machine (you can start a Python web server on your attacking machine with the python3 -m http.server 9000 command and use wget [REDACTED] to download it to the target machine)."

the wget command should probably be modified to make it more clear what we're doing even if it should be fairly obvious to someone that gets this far into the learning path. I assume it's just a simple variable goof up but when you launch the VM it changes to "http://ATTACKING_10.10.X.X:9000/PAYLOADGOESHERE.ELF"

finite gyro
#

I think https://tryhackme.com/room/owaspjuiceshop the server have some issues, I was doing the Task 4: Brute force, Instead of getting 401, I am getting 500 (Internal server error), and I heard it does not take too long to run the 1050 passwords, it took 1.5 hour for me to get to 430 / 1050 passes

eternal summit
quaint bone
#

I assume you meant @quaint bone but, I agree. πŸ™‚

eternal summit
quaint bone
#

oh my bad.

royal grail
livid escarpBOT
#

Gave +1 Rep to @glad badger

rugged canyon
#

there is another version number in one of the other results that is the correct answer

#

if you have not noticed already

royal grail
#

yeah sorry i just noticed

rugged canyon
#

well no problem then

timid burrow
#

Hello, at Upload Vulnerabilities Task 7 i cant reach demo.uploadvulns.thm it leads me to this https://www.youtube.com/watch?v=dQw4w9WgXcQ lol. I have done the instructions to change the hosts. . The other sites as overwrite.uploadvulns.thm it works perfect. Someone "hacked" the site :P?

eternal summit
#

You are explicitly told that demo is just for demonstration in the room and you are not told to navigate to it

#

In the real world, attacking a target that is out of scope can get you in a LOT of trouble in a penetration test.

timid burrow
livid escarpBOT
#

Gave +1 Rep to @eternal summit

bronze mason
#

Minor bug accidentally found in nmap -> task 3 nmap switches -> Question: How would you tell nmap to scan ports 1000-1500? Typed accidentally -p 100-1500 and it gave me correct answer.

median coral
bronze mason
#

oh okay, thx!

eternal summit
#

-ban @warped kestrel -ddays 1 Nitro phishing. Please secure your account and then appeal this ban by emailing bans@tryhackme.com

livid escarpBOT
#

πŸ”¨ Banned SJoker#7239 indefinitely

plain sandal
#

had to restart the vm every 5min almost

plain sandal
#

yep, confirmed that i still have inet, and in the rick room the static pages still work, only the php stuff dies

royal grail
obsidian kiln
#

Chances of it being the room are incredibly slim -- it's worked absolutely fine for literally about 3 years, and hasn't been updated

obsidian kiln
plain sandal
plain sandal
twin tapir
drowsy gale
white wren
#

Basic Info
Browsers: Vmware Kali (Firefox) vs Host MacOS (Brave)
RoomId: Skynet

white wren
#

Maybe this causes by inappropriate fonts in browser.

glossy crane
#

Hi, in the room Post-Exploitation Basics, task 2, Enumeration with Powerview content should be changed, Powerview is deprecated (maybe update it to something like winPEAS?)

glossy crane
#

is this a joke? 😫

quaint sparrow
#

No.

#

It wasn't.

#

It's no longer valid however.

glossy crane
#

Then maybe it should be more clearly advertise... it is extremely misleading

#

why keep it here?

#

so easy to fix

obsidian kiln
# glossy crane why keep it here?

That, is an extremely good question. It's been raised with the site staff, which is all we (as the community) can do unfortunately

glossy crane
#

i see

glad badger
# glossy crane

I've forwarded this again. Thank you for the reminder. πŸ™‚

livid escarpBOT
#

Gave +1 Rep to @glossy crane

obsidian kiln
#

Thanks Tim :)

glad badger
glossy crane
#

with the same code?

#

those are really good news

#

thanks @glad badger

livid escarpBOT
#

Gave +1 Rep to @glad badger

quaint bone
#

I'm on https://tryhackme.com/room/linprivesc Task 9 and I can't get a a reverse shell. I've done everything as correct as I can and I've referred to several writeups and I just can't seem to get it to connect to my listener. I assume the cronjobs are just not running perhaps? I did manage to answer the questions as I was able to escalate privileges with the dash binary that has a SUID bit set. I assume that's not intentional?

quaint bone
#

no... I assumed it wouldn't give me root if I ran it as karen.

#

I already terminated the session, but I'll give it a try again later and get back to ya

indigo stag
#

@dusky junco

fathom ermine
#

tryhackme.com/room/somesint aka KaffeeSec
Not exactly a bug, but idk if it should go anywhere else. At Task 4/Last question Check the shadowban api ..., that site went down about 5 months ago.
Searched and found that people did mention it, after approx. 10m they found the answer (write-ups!, most probably) and none continued with the bug/problem. Although it's easy to solve it, shouldn't that question be removed or replaced?
Cc @burnt palm (guessing you're the creator/ of the room)

wheat fractal
#

hello i think i found a bug ?

https://tryhackme.com/room/httpindetail

i already solved all the questions correctly and passed the test 100%, but I did not get a badge and the room was not counted as passed, although when I entered the room, I found that all the questions were passed correctly

#

so what can i do ?

quaint sparrow
#

IIRC that room doesn't give you a badge.

wheat fractal
#

although when I entered the room, I found that all the questions were passed correctly

twin tapir
#

Did you answer every question

wheat fractal
#

Yes sir

twin tapir
#

You said you passed the test but not answer every question

#

on each task?

wheat fractal
#

yes

twin tapir
#

Can you show a screenshot?

wheat fractal
#

All seven missions have a pass mark next to them and I have not been given room

#

i can't send any file here

twin tapir
#

Verify

wheat fractal
#

from where ?

quaint sparrow
#

!docs verify

tropic flameBOT
quaint sparrow
#

Follow that URL.

wheat fractal
#

i did it already

#

thx

#

@twin tapir

quaint sparrow
#

It says there the room is done.

wheat fractal
#

look ?

quaint sparrow
#

That's a different room.

#

That's the room you just done.

wheat fractal
#

wait

#

look

eternal summit
#

@glad badger Can you see how this redirect causes issues?

quaint sparrow
wheat fractal
#

how its even that possible

eternal summit
# wheat fractal look

There's a redirect. It's bad, we keep complaining about it. You can't access the Web Fundamentals room at the moment.

quaint sparrow
#

Ah, the redirect is the issue

wheat fractal
#

so how can i acess to web fundamentals room ?

eternal summit
wheat fractal
#

well I'm so sorry to bother you .

glad badger
#

I've made the Web Fundamentals room private again, so it doesn't show up in search results. πŸ™‚

eternal summit
glad badger
#

It's one of the rooms that have been retired from the platform. The redirect exists for a few of the retired rooms that were still popular. πŸ™‚

quaint bone
#

I uh, probably had a typo in my payload. It worked fine when I tried again earlier. Thanks.

livid escarpBOT
#

Gave +1 Rep to @vital vine

quaint bone
#

I am curious if the dash binary on that VM is intentional however. I was able to get around my messed up payload by just escalating with that binary as it has the SUID bit set.

#

fair enough.

#

thanks again @vital vine

livid escarpBOT
#

Gave +1 Rep to @vital vine

wheat fractal
#

if that even possible i really want to join this room

eternal summit
wheat fractal
livid escarpBOT
#

Gave +1 Rep to @eternal summit

wheat fractal
#

Room "Throwback" is a Free room, it's a lab so you have to pay to do this, shouldn't this be moved over to the subscription only section?

eternal summit
#

A free tier user can pay for Throwback and complete it

#

Moving it to the subscriber section would prevent that.

wheat fractal
#

Ooh ok, my bad, thanks for the info

glad badger
wheat fractal
#

Because I really wanted the badge

#

There is no reward for anyone who finds a bug lol 860161576326004746

quaint sparrow
#

!docs bug-bounty

tropic flameBOT
glad badger
wheat fractal
wheat fractal
quaint sparrow
#

With the exception of a few,

wheat fractal
#

And do you think the redirect error is even worth the reward? They are trying to get vulnerability not a bug

quaint sparrow
#

I don't think it was error, but Tim can tell you far more than I.

glad badger
#

I'll double check what the Webbed badge is attached to.

wheat fractal
#

Well now I think I lost my chance to get the bug bounty rewards and I lost my badge too. Right ?

dusky junco
#

the bug bounty program is for security issues for the platform (:

#

Tim's raised the issues re. the badge to the right people for it to be looked into. Thanks for reporting

wheat fractal
#

Thank You Anyway

glad badger
livid escarpBOT
#

Gave +1 Rep to @glad badger

wheat fractal
real hedge
#

hey guys. I tried to establish a ssh connection in Linux fundamentals 2 but the password "tryhackme" doesn't work. Some idea?

#

sry for wasting your time... after trying with AttackBox/Kali, it works openvpn at least...

glad badger
#

Enrol? Is British English spelling. πŸ™‚

eternal summit
#

-ban @cunning cove -ddays 1 Your account has been hacked and used to send phishing scams. Please secure your account and then email bans@tryhackme.com

livid escarpBOT
#

πŸ”¨ Banned namaloom#6887 indefinitely

scarlet imp
#

@hazy hinge room OSQUERY Task 7 number of features added by polylogyx needs to be updated in accordance with the readme posted on github

cosmic hedge
#

Hi, I've got problems with the room "Attacking Kerberos". I can't enumerate the box. Here is my output. /etc/hosts is correct. I can ping the maschine.
./kerbrute_linux_amd64 userenum --dc CONTROLLER.local -d CONTROLLER.local User.txt

__             __               __     

/ /_____ / / _______ / /
/ //_/ _ / / __ / / / / / __/ _
/ ,< / __/ / / /
/ / / / /
/ / /
/ __/
/
/|
|_
// /.
// _,/_/___/

Version: v1.0.3 (9dad6e1) - 05/16/22 - Ronnie Flathers @ropnop

2022/05/16 06:51:39 > Using KDC(s):
2022/05/16 06:51:39 > CONTROLLER.local:88

2022/05/16 06:51:39 > Done! Tested 1593 usernames (0 valid) in 0.345 seconds

rustic epoch
#

Can we report typos as bugs as well?

eternal summit
#

Yes

hazy hinge
livid escarpBOT
#

Gave +1 Rep to @scarlet imp

eternal summit
#

-ban @quasi lantern -ddays 1 Your account has been hacked and used to send phishing scams. Please secure your account and then email bans@tryhackme.com

livid escarpBOT
#

πŸ”¨ Banned scorpion K#4988 indefinitely

eternal summit
#

This is not a room bug

upbeat vector
eternal summit
wheat fractal
#

Packets and Frames room asks to "terminate a static site lab", when you can't terminate sites in the same way you can terminate boxes

drifting elk
#

Question, I'll try and keep it spoiler free. I noticed that RA and RA2 are vulnerable to a certain exploit that would allow acquiring the flags in about 15 minutes tops. I presume the point was not to utilize this?

obsidian kiln
drifting elk
#

Cool thanks, I'll ignore that then!

median coral
#

you might have an adblock running

fading drum
fading drum
livid escarpBOT
#

Gave +1 Rep to @median coral

copper cypress
#

I'm not sure whether this should go to #room-bugs or #site-bugs, but I decided to post it here.
There seems to be a minor bug with one of the answers.

https://tryhackme.com/room/bufferoverflowprep
Room: "Buffer Overflow Prep"
Task 4 "oscp.exe - OVERFLOW3"

The second answer to "oscp.exe - OVERFLOW3" appears to have a minor bug where one bad char is omitted.
The site expects us to answer with just "\x00\x11\x40\x5f\xb8\xed", while "\xee" is also a bad char.
To make sure it's not a problem on my end or a once off glitch, I tried the most basic troubleshooting like restarting my VPN connection, as well as restarting the entire box. However even after the restart, "\xee" still seems to be a bad char with that particular executable.

eternal summit
copper cypress
#

Of course

#

This is how the ESP dump looks even with the \xed removed but \xee not

stable quail
#

All room related to bloodhound, like Post-Exploitation Basics might need to be review, as seems that the ShapeHound.ps1 and Bloodhound being used is not up-to-date. If someone using their own PC/VM instead of Attackbox, the exported json is just simply unable to be imported, and the run down would be a bit different with the new Sharphound.exe/Azurehound.ps1 to finish the task

dense garnet
#

@gleaming shadow @minor goblet

minor goblet
#

Uhmm...

#

Please secure your account.

dense garnet
#

That’s new haha

minor goblet
#

Change password and all the things.

dense garnet
#

THE VIRUS HAS BECOME SENTIENT!!!kekw

minor goblet
#

Looks like you have spammed this in a lot of channels. I'mma ban you but once you take control of your account sent mail to bans@tryhackme.com .

#

-ban 588781239956144192 -ddays 1 Nitro phishing Please secure your account and then appeal this ban by emailling bans@tryhackme.com

livid escarpBOT
#

πŸ”¨ Banned Spazod#0123 indefinitely

minor goblet
#

@dense garnet thank you for notifying.

livid escarpBOT
#

Gave +1 Rep to @dense garnet

warm galleon
#

does anyone have an issue that opens a random VM and not the one for the module?

errant current
#

I'm getting RickRolled in the Upload Vulnerabilities room - not sure why ^^ As described in Task 1 I modified the hosts file, but when I try to access http://demo.uploadvulns.thm/uploads I am redirected to youtube. I have captured the traffic with burp and it looks like the is a redirect on the uploads page. Does anyone else have this issue?

eternal summit
#

It very explicitly says you're not meant to access demo

#

Going outside of scope on a penetration test means you're breaking the law. It's very important to read.

errant current
#

Ahh, ok thanks - now it works πŸ™‚

eternal summit
#

It's dangerous to assume it's broken just because it's not doing what you'd expect

errant current
#

πŸ‘

untold pollen
#

Jfyi, I got a 500 when uploading a valid file in client-side bypass in https://tryhackme.com/room/uploadvulns. Re-deploying the room machine helped.

wheat fractal
#

Hello

#

The binary of this box was don't executable

quaint sparrow
#

Chmod +x filename

violet hedge
#

I'm trying to create a room, but after uploading the VM image which is based on ubuntu 20.04, its showing "Problem converting VM. Check prerequisites.", but they all seem to be matching

violet hedge
eternal summit
#

That won't work

violet hedge
eternal summit
#

Ubuntu server

violet hedge
livid escarpBOT
#

Gave +1 Rep to @eternal summit

eternal summit
violet hedge
proud delta
#

I'm trying to do the Plotted-TMS room but every 3 minutes everything crashed it is impossible to complete an nmap let alone a gobuster/nikto scan, it's been three days since I have noticed these kind of bugs/lags... on many rooms is it normal ?

eternal summit
finite gyro
eternal summit
#

You are explicitly told not to navigate to demo.uploadvulns and you are never told to interact with it

#

Attacking hosts that are out of scope is illegal, you need to read very carefully because if this was the real world in a penetration test you could be in a lot of trouble

finite gyro
livid escarpBOT
#

Gave +1 Rep to @eternal summit

obsidian kiln
#

Heh, that's a new one.
Reading the instruction that says the site literally doesn't exist, then attacking it anyway kekw

eternal summit
#

-ban @dusky harness -ddays 1 Nitro phishing, please secure your account and then email bans@tryhackme.com to appeal

livid escarpBOT
#

πŸ”¨ Banned S7ven#2647 indefinitely

sick scroll
#

Hey'o! β˜•
The room "Empire" doesn't load images in task 5, task 6 and task 8. (Only 1 image in task 8). Checked with 2 devices and they are gone on both.
Link to room: https://tryhackme.com/room/rppsempire

forest shard
#

Not a bug but the experience with the Windows Server in room introtoshells task 13/15 is very bad with just 1GB of RAM.

obsidian kiln
weary jungle
#

Hello. Not sure if it's bug but my experience with room Post-Exploitation Basics has been quite awful. Unable to connect to the windows server with rdp and ssh hangs quite often, even after 1 hour. If someone could check it. I would be grateful, thanks. https://tryhackme.com/room/postexploit#

obsidian kiln
#

@twin tapir

forest shard
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

eternal summit
#

-ban @sudden geyser -ddays 1 Your account has been hijacked and used to send phishing scams. Secure your account and then appeal this ban by emailing bans@tryhackme.com

livid escarpBOT
#

πŸ”¨ Banned its_tym#2166 indefinitely

eternal summit
#

-ban @wheat fractal -ddays 1 Your account has been hijacked and used to send phishing scams. Secure your account and then appeal this ban by emailing bans@tryhackme.com

livid escarpBOT
#

πŸ”¨ Banned RTWarpath#8329 indefinitely

fathom fiber
#

Vulnversity room - I cannot get the webpage to load in attack box, keeps giving me SSL_ERROR_RX_RECORD_TOO_LONG error

eternal summit
fathom fiber
#

got it thanks

weary jungle
glossy quest
#

weirdest bug ever reported onTHM?

jagged drift
#

Hello

#

it's not specified that you need to put the port of your netcat command

#

And I think It can be confusing for beginers

#

Oh well my bad

leaden kayak
#

https://tryhackme.com/room/introtolan
For example, a device with the IP address of 192.168.1.100 will be on the network identified by 192.168.1.0
This is not necessarily true unless you specify you are on a /24 network

eternal summit
leaden kayak
velvet belfry
#

Don't know how to contact the room author to suggest an edit but maybe someone from the mod team or staff can address this? So:
https://tryhackme.com/room/johntheripper0
In Task 1, section "What makes Hashes secure?" the author seems to confuse P and NP concepts. Generally they would work the other way around. Also these refer to decision problems and I'm not sure if you can formulateΒ obtaining a preimage of a hash in a way that it falls in that problem category at all. It's cool that it's at least mentioned but maybe just rewrite that section?

finite gyro
#

Hello, I might have broken something: Upload Vulnerabilities
https://tryhackme.com/room/uploadvulns
I was doing the task 11: challange
things did not work as they were supposed to be, so I restarted the machine
I get the IP address, but it is not loading the web page.

Does it mean I have to re-do everything from scratch?

#

jewel.uploadvulns.thm does no longer load

quaint sparrow
#

Did you put it in your hosts?

eternal summit
finite gyro
#

thank you

#

I did that

graceful aspen
#

Hello, been a while since I came here. I have encountered a problem in the VM attached to the tasks in DNS Manipulation room https://tryhackme.com/room/dnsmanipulation

In "Data Exfiltration", the python script packetyGrabber.py that re-assembles the file from the .pcap file, decodes, then outputs it doesn't execute correctly. I thought it was my error because in the task, the author does say to ignore the error after executing the script. But I spent all 2 hours of the VM trying to make it work. I tried messing with the code and that didn't get me anywhere.

After those hours, I just scp'd the challenges directory to my machine and ran the script and viola! No error and got the re-assembled file correctly.

If someone can get in touch with the author to make sure, I'd appreciate it.

pliant zodiac
#

hi guys i have a problem with the Blaster room

#

i can't find the history in the explorer browser

#

they are only today history

ebon otter
#

no wonder i kept getting error with the last question in Task 3 in the "Windows Fundamentals 1" room, it demanded another answer then what the OS says itself it called, so despite i being correct, the OS used another spelling.

eternal summit
#

-ban @cerulean kayak -ddays 1 Your account has been hacked and is being used to send phishing scams. Please secure your account and then email bans@tryhackme.com to appeal this ban

livid escarpBOT
#

πŸ”¨ Banned Default#5248 indefinitely

eternal summit
#

-ban @kindred gazelle -ddays 1 Your account has been hacked and is being used to send phishing scams. Please secure your account and then email bans@tryhackme.com to appeal this ban

livid escarpBOT
#

πŸ”¨ Banned _blankMahir#6812 indefinitely

crystal verge
crystal verge
#

ok

fading elk
#

Hi, i have a bug in the room "Living Off the Land"

#

when i try to rdp with xfreerdp

median coral
#

Can you link the room as well?

fading elk
eternal summit
#

-ban @rustic crag -ddays 1 Distributing malware

livid escarpBOT
#

πŸ”¨ Banned trevor scotland#5095 indefinitely

wheat fractal
#

Hey, not really the bug, but the room may need a bit of actualization :) In Web Enumeration room, in task 9, subtask 2, system does not take answer from scan result because it was created some time ago when current 'latest version' did not exist yet. https://tryhackme.com/room/webenumerationv2

Also, the room https://tryhackme.com/room/rpwebscanning linked at the end is no longer accessible (owner has made this room private). - it is linked twice.

buoyant night
atomic wagon
#

Hey does anyone has a solution to make Splunk work in the Incident handling with Splunk Room???
getting a " This browser is not supported by Splunk.
Please refer to the list of Supported Browsers." message everytime

atomic wagon
#

Mozilla but also tried chrome same thing

median coral
atomic wagon
median coral
#

firefox

#

also, can you share the machine ip if it doesnt work?

atomic wagon
#

Sure

#

10.10.66.81

#

Ja also trying with Firefox right now

median coral
#

It works for me

#

Β―_(ツ)_/Β―

atomic wagon
#

πŸ˜‘πŸ€”

median coral
quaint sparrow
#

They are connected to the VPN?

median coral
#

I hope?

quaint sparrow
#

Could be the reason why they're not being able to connect

atomic wagon
#

ok got it

#

thank u guys

ripe patrol
void vortex
#

https://tryhackme.com/room/windowsforensics2
I'm having issues with the VM in Windows Forensics 2. I've only been able to successfully spin it up once. Can someone take a look at this?
It crashed after 5 minutes, every attempt to spin it up again has failed.

misty cave
void vortex
#

I saw that mentioned in #site-bugs, ill try a bit in a few. Thanks for the response.

eternal summit
#

-ban @tawny rivet -ddays 1 Posting scams

livid escarpBOT
#

πŸ”¨ Banned Hayyan#9198 indefinitely

fiery flint
hot lintel
#

Hello. I'm trying to do Upload Vulnerabilities room. I keep getting timed out from all of the diffrent adresses (like jewel.uploadvulns.thm) I have terminated and reloaded the room, several time. Cleared cookies. checked /etc/hosts, firewalls. But the problem persists. I have maybe 2 minuts before the room times out, for 8min. I connect trought openvpn and use my own Kali. Anyone ells having these problems?

eternal summit
hot lintel
#

ok thanks

azure umbra
#

for idsevasion room only suricata is detecting scans, even for the example scans that are supposed to be detected by Wazuh. I've tried spinning up the room twice with same results.

rugged canyon
#

@obsidian kiln ⬆️

obsidian kiln
#

-ban @wheat fractal -ddays 1 Nitro Scam -- compromised account

livid escarpBOT
#

πŸ”¨ Banned DragonHunter#7999 indefinitely

dense garnet
#

@gleaming shadow @obsidian kiln

tame karma
#

The conclusion of the Network Miner room links to a room called "Brim." That link goes to a page with an error. https://tryhackme.com/room/brim

#

Owner has made this room private.
If this is an error on our behalf. Please contact us.

quaint sparrow
fallen geyser
#

Is the command injection task 5 for jr pentester supposed to display β€œweb page @ might be down/ may have moved permanently” I’ve been seeing it for a couple hours now.

plain jasper
#

Hello, I was doing the burpsuite rooms and in one of them ,Burp Suite: Repeater; Task: 8 SQLi with Repeater, (https://tryhackme.com/room/burpsuiterepeater) there is a link to a room for SQLi (https://tryhackme.com/room/sqlibasics) however it leads to a page which says that the room has been made private by the owner.

#

(not sure if that should be considered room-bug or site-bug, sorry if I've put in the wrong channel)

dusky junco
#

-ban 245291806244339712 -ddays 1 nitro scam

livid escarpBOT
#

πŸ”¨ Banned gerbsec#1956 indefinitely

hazy saddle
#

In the SQL Injection room I started up the machine but it keeps telling me the vm/machine cannot be reached and may be temporarily down. I refreshed and restarted the page a few times and same issue. Maybe its just a temp issue but wanted to put it out there

#

Ah gotcha lol

dusky junco
#

I’ve raised this to the appropriate people (: thanks for the screen grabs

livid escarpBOT
#

Gave +1 Rep to @vital vine

dusky junco
livid escarpBOT
#

Gave +1 Rep to @vital vine

regal thorn
#

client-side input filtering suggested to prevent command injection

vague kite
#

Hey guys, I can't validate the path to files secrets.txt and realsecret.txt in the room meterpreter. The path is correct because I could extract the content of the files. Any idea? => Okay nevermind, the path must not contain the file name to be validated.

finite gyro
#

Hello, might there be a bug at the task 8 of Cross-Site Scripting room (https://tryhackme.com/room/xssgi)

I got the base64 (c2Vzc2lvbj1mMmFiZThiZGFiZDBkNDY4ZjNiNjJiOTFiMjg1ZTA1OA==)
and decoded it as session=f2abe8bdabd0d468f3b62b91b285e058 with both kali linux and https://www.base64decode.org both of them gave me the same result. However
it does not accept the answer

  • cookie=c2Vzc2lvbj1mMmFiZThiZGFiZDBkNDY4ZjNiNjJiOTFiMjg1ZTA1OA==
  • c2Vzc2lvbj1mMmFiZThiZGFiZDBkNDY4ZjNiNjJiOTFiMjg1ZTA1OA==
  • session=f2abe8bdabd0d468f3b62b91b285e058
  • f2abe8bdabd0d468f3b62b91b285e058
    I do not know what to type in here
finite gyro
#

Best Regards

hazy saddle
#

Are you clicking the ticket before you let it automatically send you the cookie? You may be getting your own cookie if that is the case. I had that issue, if I am understanding your issue correctly.

#

@finite gyro

chilly pasture
#

I'm in Web Enumeration Room Task 9. I think there is something wrong with the wordpress box as WPScan was unable to detect the main theme. Same results after restarting machine thrice

#

"The main theme could not be detected"

vital pine
#

Hi guys, I have a problem with Burp room. I've done it but it still appearing as available. What can I do?

rotund burrow
#

Ohh no i think i'm wrong this happened when the room was part of a path but if you have all the tasks inside it completed i think it's something else, saw some other complaining a while ago about this but can't remember what caused it or how to fix it

finite gyro
livid escarpBOT
#

Gave +1 Rep to @hazy saddle

finite gyro
#

Thanks, appreciated

regal thorn
#

https://tryhackme.com/room/owaspjuiceshop task 7, all three questions are broken. For the first 2, I don't get the flag. For question 3, the exploit doesn't work. I can't even debug the javascript properly on catching the click event. I get stuck in an event handler loop without being able to inspect the JS variables! Is this a browser thing? I noticed that the VM is not identical to the questions, the shipment ID is different.

#

I tried Chrome and Firefox, my own Kali VM and AttackBox.

#

Basically, the Angular app won't respond to changes after the # fragment identifier, after the initial page has loaded.

#

So I load the /#/track-result?id=xxxx-xxxxxx page and it shows, but changing anything after the id= doesn't do anything at all

golden nimbus
#

https://tryhackme.com/room/activedirectorybasics task 8, link provided to powerview on github is for powerview3, deployed Windows machine has installed Powerview2, link or Powerview on virtual machine should be changed in order not to waste other users' time looking for a solution

uncut bramble
#

Is anyone doing Task 13 of the Burp Suite: The Basics

#

The instruction say Take a look around the site on http://MACHINE_IP/

#

which I am assuming means to browser to the AttackBox's IP in a browser, but I am just getting error ```Error response

Error code: 405

Message: Method Not Allowed.

Error code explanation: 405 - Specified method is invalid for this resource.```

#

haha okay

#

got it thanks. doing it in pieces with large gaps inbetwwen, fotgotten that nugget of info

#

thank you

obsidian kiln
hazy hinge
drowsy gale
#

replying to a month old question πŸ˜† it wasn't there at the time.

fossil turret
#

the root.txt flag do not seem to be on alfred box anymore

hazy hinge
eternal summit
#

This should be a lesson about reading the content too.

wheat fractal
indigo stag
obsidian kiln
regal thorn
eternal summit
eternal summit
#

I'm not staff, don't ping me for bugs please.

regal thorn
#

didn't mean to, sorry!

median coral
#

eternal blue can take a few tries to work but you might have an error in your setup too

regal thorn
smoky cosmos
#

Hey I dont know if it is my machines problem (kali linux 2022 latest version) but in the blue room the meterpreter session is really unstable and some times the auxiliary scans i used on the target box said that it is not vulnerable to eternal blue ms17-010

#

Restarted the vpn and the machine 2 times but the sessions were still unstable

median coral
#

!dark

tropic flameBOT
#
DarkStar7471
*ahem* Can help you?
median coral
smoky cosmos
crystal pagoda
#

I am having the exact same issue

oblique mural
#

In room monitoringevasion i in the agent.exe from the source code I don't see a call to the getflag static method. And it seems like agent always returns the same error

wispy locust
#

Hi. In the Brainstorm room the answer to number of open ports is 6, however there are only 3 ports open (even googled other people's walkthroughs to confirm)

knotty drum
#

hi

#

The type of trusts put in place determines how the domains and trees in a forest are able to communicate and send data to and from each other when attacking an Active Directory environment you can sometimes abuse these trusts in order to move laterally throughout the network.

#

this is in Active Directory Basics

#

it needs punctuation

dull prairie
dusky junco
dull prairie
#

Yay!

#

Thank you so much!

dusky junco
#

Gotta get that Splunk fix 😎

dull prairie
#

Oh yes indeed : )

#

Thanks again Ben!

dusky junco
#

anytime!

hearty fulcrum
#

Ooooh, so the 101 was already the room to do before. Ok gotcha I can continue so thanks lol

eternal summit
#

-ban @wheat fractal -ddays 1 Nitro phishing. Secure your account and then appeal this ban by emailing bans@tryhackme.com

livid escarpBOT
#

πŸ”¨ Banned MorganHartman#9069 indefinitely

hardy kestrel
#

https://tryhackme.com/room/networkservices : Task 7 - Exploiting Telnet
The remote subject telnet server only allows running one command per session (when connected). After that it freezes completely and requires a VM reboot; making a second session causes it to be frozen as well. For instance I run .HELP, it shows possible commands properly, then no action can be taken (even ctrl+c does not work). Exploiting this server right away after making connection like .RUN <payload> works.

cosmic remnant
#

I am doing the tech support room and trying to run a script but it giving me a wrong creds, I got then and decrypted them and can log in on the web but can get in with this script

#

got it for got the / in the url at the end

leaden kayak
dusky junco
livid escarpBOT
#

Gave +1 Rep to @leaden kayak

leaden kayak
#

Why is robocop unable to give me rep ? :(

dusky junco
#

it's based on certain keywords like thank, thanks, ty

leaden kayak
#

Why does it say invalid user ?

dusky junco
#

Could be caching

#

we're a big server

#

but there you are

leaden kayak
dusky junco
#

You should be able to use -rep for your user (:

#

so just

#

-rep

#

rip

leaden kayak
dusky junco
#

indeed (:

#

perhaps infamous

#

I'll let you decide πŸ˜„

vagrant heron
#

Room: Living of the Land

Error message:
"Connection Error - The remote desktop server has denied access to this connection. If you require access, please ask your system administartor to..."

Can not either connect through embedded attackbox or my own Kali VM.

pulsar yew
#

this room has been made private

#

Do I have any way to access it

eternal summit
pulsar yew
eternal summit
#

Go to hacktivities and search for splunk

pulsar yew
#

ok thanks

pearl socket
#

Hi guys,
I am doing the log4j room ,
the ldap server is running correctly (marshalsec), the python http server running correctly and giving the Exploit.java, but the reverse shell with nc , I am not getting , can't understand what is the problem

pearl socket
#

so it can't be a bug ?

eternal summit
pearl socket
untold nimbus
#

the CC pentesting room

vagrant heron
spark apex
#

Apparently the flag it displays is incorrect

#

this issue is also mentioned in the thread for this room with the correct answer

quaint sparrow
#

Can you paste your answer here with spoiler?

quaint sparrow
spark apex
#

||THM{1Nj3c7_4LL_7H3_7h1NG2}||

#

just replacing the "I" with "L"

quaint sparrow
#

Yeah, as I suspected.

#

I think it's a 1.

#

No, it's a l.

spark apex
#

it's l

quaint sparrow
#

I think because I don't think you can copy from the box.

misty cave
quaint sparrow
#

I had trouble with that, but that was on my Vm.

misty cave
spark apex
#

Gotta do rdp into the box to copy ig

median coral
#

@hazy tiger

hazy tiger
#

-ban 559932466320900117 -ddays 1 Nitro Scam

livid escarpBOT
#

πŸ”¨ Banned Stewie Griffin#9805 indefinitely

north verge
#

there is no option to open the link even after initializing both internet explorer and google chrome.

eternal summit
#

Intended. Not a bug, still exploitable@north verge

north verge
eternal summit
#

It's not a bug though

#

It's actually intentional from the room creator

north verge
#

owh, so this path is like a rabbit hole?

eternal summit
#

No

#

It's exploitable.

#

It's not a bug, it's just something that makes the exploit more difficult. Fully intended

eternal summit
#

Really? Urgh

#

-ban @proper pewter -ddays 1 Nitro Scam

livid escarpBOT
#

πŸ”¨ Banned Vaishnavu C V#8844 indefinitely

frigid plover
#

Not a bug per se...
But https://tryhackme.com/room/agentsudoctf
I guess I should have remembered the room name. But running linpeas you get one possible CVE to exploit (which works) that's not the intended "room name" way. Due to the room being old and not patched.

But anyway, due to linpeas giving me this, I got a bit confused by the question here. The format the question asks for is CVE-XXXX-XXXX . so 4 x's on both places.
The intended CVE wanted contains 5 x's at the end. Maybe at least update the question text? πŸ˜„

heady rapids
#

My scans come up with ||1 open port||

spare terrace
fathom oar
#

The Machine in the network services room in the telnet section isn't stable...it keeps going dead

quaint sparrow
#

@dusky junco

median coral
#

@dusky junco

#

πŸ‘€

dusky junco
#

-ban 277913887666339840 -ddays 1 nitro scam

livid escarpBOT
#

πŸ”¨ Banned ZeniKen#5217 indefinitely

dusky junco
#

ty

normal void
#

is it just temporary bug?

#

ok

last oyster
#

Hi, It seems he https://tryhackme.com/room/xssgi Task 8 Practical Example (Blind XSS) is broken. I set up the listener and when I open the ticket, I get my cookies, but I never got any staff-session.

last oyster
livid escarpBOT
#

Gave +1 Rep to @eternal summit

swift lava
#

Hello,

#

I have a doubt in room Hacking with powershell last task named Intermediate scripting

#

tcp connection is only succeeding on ||1 port but answer is 11|| in range 130 to 140

#

do we have to answer on basis of pings?

twilit flume
#

Hi, not sure where this should go, but OSquery room, task 4, the number of tables available at version 4.7.0(as per screenshot), is not accepted as the correct answer as neww tables have been addedd. Same room task 6, the osquery version deployed is 4.6.0.2, but the task only accepts 4.2.0 as the correct answer

pastel talon
#

Hello, I was doing THM Wreath Network https://tryhackme.com/room/wreath.
And for some reason,, I get thrown out of the room. All the progress I have made resets automatically.
This is 2nd time I have experienced this in the last 3 days.
Can someone help me with this?

quaint sparrow
#

The server chucks everyone out after x amount of days ( I think Wreath is 7 ) you just download a new vpn pack then re-join the room.

pastel talon
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

quaint sparrow
pastel talon
quaint sparrow
devout flume
#

Don't know if you'd call it a bug but Encryption - Crypto 101 recommends you to complete CCPentesting prior to the room but it's a private room

leaden kayak
eternal summit
leaden kayak
#

Lol sorry

untold nimbus
#

Blue
it ask to use this payload windows/x64/shell/reverse_tcp

#

but it doesn't work

#

use the binded payload and it work

rain wing
#

Heya, I wouldn't call it a bug but I'm not sure where else to point it out. You guys are probably already aware of it, but just in case: I just did the NMAP introduction room Task 2 question 3. [Research] How many of these are considered "well-known"? (These are the "standard" numbers mentioned in the task). It asks for the number of well known ports but it doesn't accept the "correct" answer I got from google ||1023||, but instead it accepted ||1024||.

quaint sparrow
#

It's 0-1023.

#

So it's 1024.

rain wing
#

Ohhh that makes sense xD I did not think of that!

#

thanks!

hazy tiger
#

-ban 730386604144984125 -ddays 1 nitro scam

livid escarpBOT
#

πŸ”¨ Banned penguencici#6464 indefinitely

spark crag
#

The logging tool for That's the Ticket doesn't appear to be working. Idk if this is a new or old problem. The room works fine with ||Burp Collaborator|| but the same code would not work with the logging tool. FYI

median coral
spark crag
#

would've been nice to know that up front

median coral
#

Yeh, there should be a disclaimer on there

solar drum
#

@icy elbow

icy elbow
#

-ban 858405211173683210 -ddays 1 Nitro scam

livid escarpBOT
#

πŸ”¨ Banned saknks#5733 indefinitely

icy elbow
livid escarpBOT
#

Gave +1 Rep to @solar drum

rotund burrow
#

@gleaming shadow

gleaming shadow
#

sigh

spark crag
misty cave
livid escarpBOT
#

Gave +1 Rep to @spark crag

spark apex
#

Not a bug , but a line is repeated in task 35 of holo

eternal summit
#

@misty cave (It won't work)

spark crag
#

It did work tho

#

I had my Kali VM connected to the THM network and then ran Burp within the VM

eternal summit
#

Because your browser has internet access

#

The target machine absolutely cannot send it's token to collaborator.
It cannot even resolve the domain, let alone communicate with it.

spark apex
#

i once encountered this too

#

i was doing an csp lab and used beeceptor which worked for the lab

#

idk how

spark crag
#

Except that it did work. You can try it yourself

eternal summit
#

Won't on THM unless the box has internet access.

spark crag
#

Again, you can try it yourself to get the email

misty cave
#

Looks like we've got the DNS and logging tool up instead

paper grotto
#

I found a bug//incorrect info in a room should I send a feedback via the feedback and ideas or just drop it in here?

#

Spotted a bug: One of the questions this room asks: 'What is the maximum length of a subdomain?'. The correct response would 253 however, the hint given is only two characters and the accepted answer is 63

it appears that the following question is also wrong:
'What is the maximum length of a domain name?' the hint is three characters and it wants 253 as the correct answer. Which is the correct answer to the first question. I think the answers just got flipped by accident. Not sure if this is on my end or THM

paper grotto
#

yes

#

it is fixed now

paper grotto
#

cant seem to insert an image but sent you on dms

#

that is the issue it is saying that the correct answer is 63 not 253

#

I could be misinterpreting this but the rooms says the length must be kept to 253 character or less

#

"You can use multiple subdomains split with periods to create longer names, such as jupiter.servers.tryhackme.com. But the length must be kept to 253 characters or less"

#

This is in reference to the whole domain not just subdomians?

#

Ok got it, thanks for the clarification

umbral bay
#

Hi! I'm in the Living off the Land room and can't seem to access the Windows VM from AttackBox with the given credentials.

#

can someone please help?

cloud swift
#

something is wrong with http server

median coral
cloud swift
#

it answers to icmp and I can see a port open

median coral
#

if the website is down and there's nothing about it in the associated video walkthrough, then probably best to go for a reset
you can make a reset vote every hour

cloud swift
#

yeah...

#

requires 5 people to reset

#

false alarm, sorry

eternal summit
#

@hazy tiger plz am working

hazy tiger
#

-ban -ddays 1 Nitro scam

livid escarpBOT
#
Ban <User:Mention/ID> <Duration:Duration> <Reason:Text>
Ban <User:Mention/ID> <Reason:Text> <Duration:Duration>
Ban <User:Mention/ID> <Duration:Duration>
Ban <User:Mention/ID> <Reason:Text>
Ban <User:Mention/ID>

[-ddays ddays:Whole number - Number of days of messages to delete]

Invalid arguments provided: No matching combo found
hazy tiger
#

REEEEE

#

-ban 500725169766268928 -ddays 1 Nitro scam

livid escarpBOT
#

πŸ”¨ Banned Anonymous07P#8746 indefinitely

eternal summit
#

Thanks Jabba

pulsar yew
#

in this room rar2john is not working in attackbox

#

i think something is messed up in environment path

#

Currently , we have to go in john folder then use ./rar2john

#

John directory is not set in $PATH

harsh kernel
#

is the find command room removed? there is a link linux room to it but it shows private

hazy tiger
#

@vital vine Removed that^
Private rooms are private so that people can’t access them

#

Mods != site staff, that room was replaced with a new room.

Usually we prevent teaching people how to bypass private rooms because it’s used to get into rooms that shouldn’t be accessed yet.

Boarders computer misuse when used incorrectly

cosmic remnant
#

Hello I have a possible bug in the Nessus room

#

I got the answer nevermind just thought it was weird

quaint sparrow
#

@eternal summit

eternal summit
#

-ban @wheat fractal -ddays 1 Nitro phish

livid escarpBOT
#

πŸ”¨ Banned KrazyLazySloth#6150 indefinitely

fresh yacht
#

I can't get the page in the Vulnversity room to load using the attack box. It says Firefox can't establish a connection to the server at 10.10.248.237.

eternal summit
fresh yacht
livid escarpBOT
#

Gave +1 Rep to @eternal summit

untold nimbus
#

Hello I think https://tryhackme.com/room/linuxprivesc the ssh is not working well cause I can't connect to it it said unable to find host key

#

and when I reset it's always a time out connection I get

high palm
#

it is also taking answer as gpf it should be gpg refer: Linux Strength Training Room Task:6 Question:2

#

please fix it

median coral
high palm
#

ok then no issue

eternal summit
untold nimbus
livid escarpBOT
#

Gave +1 Rep to @eternal summit

high palm
#

any one can tell me about Linux Strength Training Room Task:8 Question:1 whenever try to show data of table it throws error as Empty set (0.00 sec)

#

no issue in command though

high palm
#

?

#

this is error screenshot

wheat fractal
#

Hi All! While studying the nmap post port scans room, in the service detection section i came across this sentence: "In other words, stealth SYN scan -sS is not possible when -sV option is chosen". The next paragraph starts with this statement: "The console output below shows a simple Nmap stealth SYN scan with the -sV option". It's not a big deal anyway, I just think, that using -sV alway result in a 3-way handshake (as stated in other places and room on THM). So using the -sS option with -sV, or using only -sV always results in a 3-way handshake, not a syn scan. Am I wrong thinking that? Thanks in advance!

eternal summit
#

I'd suggest running wireshark while scanning if you'd like a deeper dive into the exact traffic you're sending

wheat fractal
# eternal summit -sV goes beyond the three way handshake, it pokes at the services too to try and...

Thank for your reply! I know that -sV grabs the banners, that's why I think it always needs the 3-way handshake. The SYN scan doesn't finish the handshake, because it ends with RST (not with ACK). At least that's how I know it. So for me, this statement is weird: "The console output below shows a simple Nmap stealth SYN scan with the -sV option", because while using the -sV option a full handshake occurs (without it no version detection could be performed). I hope I was able to describe a little better, where I'm stucked. Once again: it isn't a showstopper issue, I just wanted to clear things up. Thanks for your patience!

livid escarpBOT
#

Gave +1 Rep to @eternal summit

eternal summit
#

That's where scanning and looking at the traffic in Wireshark would help you.

#

It would tell you exactly what traffic is going over the network

wheat fractal
agile glacier
#

For Advent of Cyber 1 [2019] the day 9, Requests the given ip (10.10.169.100:3000) would seem not to work

rugged canyon
#

so either skip that task or look for a writeup to copy the answer

#

or ask shadow nicely and they can give it to you in a dm

agile glacier
#

ok, ty

leaden kayak
#

if all that is being asked is to search for the eventid, the "correct" answer is not whats in the vm

rancid coral
#

w

quaint sparrow
leaden kayak
quaint sparrow
leaden kayak
#

I searched for another eventid ( that i think is the correct one, and also contains the time entry that is deemed as correct, event though is not the first as requestes )

quaint sparrow
#

What are you putting?

quaint sparrow
#

You're looking for a ||special logon||

leaden kayak
leaden kayak
quaint sparrow
quaint sparrow
#

@hazy tiger

hazy tiger
#

-ban 695135235033137193 -ddays 1 nitro scam

livid escarpBOT
#

πŸ”¨ Banned The BeastπŸ‘‘#4535 indefinitely

hazy tiger
#

0xD my ass smh

dusky junco
#

-ban 434330011819048961 -ddays 1 Compromised account spreading nitro/scam. Secure your account by resetting your password, enabling 2FA and appealing bans@tryhackme.com

livid escarpBOT
#

πŸ”¨ Banned SpiceySec#9798 indefinitely

hazy tiger
#

Going to drop them a message on the site

dusky junco
#

someone got a little click-happy πŸ˜„

quaint sparrow
#

People really want free Nitro huh?

dusky junco
#

Apparently so

#

More over, steam just seem to be really generous

quaint sparrow
#

That's not like them xD

leaden kayak
dusky junco
#

Ah that's annoying. I'll look into this thanks (: sorry for the hassle

livid escarpBOT
#

Gave +1 Rep to @wind umbra

wise spear
wise spear
#

Task 4's last question is wrong as well

harsh kernel
#

/room/subdomainenumeration i used the original danielmiessler Seclist from GitHub and it found 3 subdomains where first one is api and 2nd and 3rd are delta and yellow which is different from attackbox wordlist it seems since my command took way longer

#

But the answers are delta and yellow instead of api and delta

quaint sparrow
#

It is.

It's not a bug however, it's just the way the word list is on the attackbox and THM staff can only assure their material only works on Attackbox.

quaint sparrow
harsh kernel
#

Alright thanks, i will do that

runic swallow
#

The Redline room (https://tryhackme.com/room/btredlinejoxr3d) desperately needs extra info for Task 6.

It doesn’t tell you that you should be analyzing an existing Redline session located in the Documents folder.
This led to me attempting to create my own session on the machine which failed over and over again, wasting hours of time waiting until I searched Google to find you weren’t even supposed to create your own session.

placid abyss
placid abyss
#

Probably

#

Β―_(ツ)_/Β―

quaint sparrow
#

@naive kayak Hi, did you create the above room? and if so possibly help out?

misty cave
livid escarpBOT
#

Gave +1 Rep to @misty cave

runic swallow
hearty fulcrum
#

There is a typo on the Network Miner room.
Also by missclicking on the hint for task 5, saying "Networkminer 2.7 can help" is not really an hint at all. Not like it needs any hint, better remove them imo.

#

this typo is there multiple times on the room

#

task 6

#

???

glad badger
hearty fulcrum
#

":workMiner" where is the net

#

:wrokMiner"

#

the last screen the sentence is butchered

#

the hint thing is another remark unrelated

glad badger
livid escarpBOT
#

Gave +1 Rep to @hearty fulcrum

hearty fulcrum
#

The room Corp just doesn't work

#

either accessing with the split view or by RDP

#

rebooted the machine already

#

the start menu does'nt work at all

#

and the first command the room tell us to try error

eternal summit
#

Your spacing is dodgy

hearty fulcrum
#

nvm

#

copy paste had more than 1 space

#

wtf

#

well command works

#

but start menu still buggy lol

#

start menu shouldn't be a problem but weird

hearty fulcrum
#

thanks for answering tho @eternal summit

livid escarpBOT
#

Gave +1 Rep to @eternal summit

coral moss
#

Dead link

#

"Linux Fundamentals Part 3"

#

Crontab Generator website is off

quaint sparrow
#

If you're a free user you won't have internet access on the attackbox.

#

Website is still online.

coral moss
#

I'm free user

quaint sparrow
#

Use your host OS to access the website

coral moss
#

But I was running the site

#

On my own virtual box

#

While connected to tryhackme by openvpn

quaint sparrow
#

That won't made a difference to your own connection.

coral moss
#

I was able to ping Google

#

So my internet was working fine

quaint sparrow
#

Can you access the website now?

coral moss
#

Let me check

#

How, it's working now

winged plinth
#

https://tryhackme.com/room/pwn101
I think challenge pwn102 in this room is not working πŸ˜•
I am getting connection refused when using nc to port 9002 (all others work fine)

terse jungle
#

https://tryhackme.com/room/burpsuiterepeater Task 8. Before we start on this challenge: if you don't already know the principles of SQLi, then it would be well worth your time checking out the room on the topic; however, full steps will be provided, so you do not need in-depth knowledge of the principles behind SQL Injection to complete this task. Room on the topic is PRIVATE.

hazy tiger
terse jungle
obsidian kiln
wise spear
#

same text repeated twice

terse jungle
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

keen bloom
#

in YARA module on Cyber defence path, im not able to connect via ssh on task 4:deploy.it says: "ssh: connect to host 10.11.69.202 port 22: Connection refused". the command i typed is: ssh cmnatic@10.11.69.202 <---(this it the ip i got for the machine and i even pinged the ip and yes it is reachable)

dusky junco
#

You are trying to ssh into your own device

10.11.69.202

#

you need to SSH into the IP in the red box at the top of the room

#

@keen bloom

dusky junco
#

can you share a screenshot?

keen bloom
#

sec

dusky junco
#

All machines that you deploy in a room are 10.10.x.x

keen bloom
dusky junco
#

That is your VPN IP

#

You need to deploy the machine in the room (Task 4) where a box at the top of the room (not page) will show the IP address that you need to use

keen bloom
dusky junco
#

np(:

primal zodiac
#

the link in machine_ip/content in the LazyAdmin room does not lead to where it is supposed to go

#

it takes you here

#

instead of here

median coral
#

welp, that answer is incorrect

#

it's literally the most common default user

restive sparrow
#

and I literally used that most common default user with $ne meaning anything except that

#

chesus crist

median coral
#

😦 I was checking that

restive sparrow
#

aaaaaa

median coral
#

yeh,

restive sparrow
#

you wanna see my actual request?

median coral
#

sure but these mistakes happen

median coral
#

nice

#

can't be admin if you're matching against it

restive sparrow
#

lmfao yeah

#

These subtle things, matter a lot, these build up experiences when interacting with certain technologies,

median coral
#

yeh, just a matter of experience

strong kelp
rapid wren
#

Anyone else having any issues of completing a room and it not fully acknowledging it? I completed the Metasploit room 100%, but it is not verifying it for me. It isn't that big of a deal, but it messes with me.

eternal summit
#

You have completed a metasploit room but not the one it's showing

#

When you click through to it, you're redirected to the new one